# flex-auth tenancy posture declaration # Framework: net-kingdom/canon/standards/tenancy-posture_v0.1.md draft-8 (§5) # Conformance rule (§6): accuracy, not altitude. This file overclaims nothing. # Reasoning and evidence: docs/tenancy-posture-review.md schema_version: "0.1" framework: netkingdom-tenancy-posture service: flex-auth role: policy-decision-point tenancy: current: I: 1 A: 2 E: 1 P: "n/a" R: "n/a" V: 0 implemented: A: 2 E: 2 target: I: 1 A: 2 E: 2 P: "n/a" R: "n/a" V: 1 reviewed: "2026-08-18" review_due: "2027-02-17" service_class: latency-critical permanent: [I, P, R] gap: I: >- Subject and tenant arrive in the CheckRequest body, asserted by the calling PEP. flex-auth verifies no token and holds no session. This is I1 by §4.1's literal rule and is structurally correct for a PDP: the decision point judges asserted claims, it cannot be the verifier of its own inputs. Not a defect and not a target for movement. A: >- All three production pins are live A2 as of 2026-08-19 on digest sha256:138aa347… with callerAuth.mode=enforce (user-engine, tenant-engine, isolated ops-warden). Unbound requests return 401; a token bound to the other protected system returns 403. Zone membership, if any, reaches this PDP only as compiled registry data — never a synchronous zone-engine lookup. E: >- No tenant data at rest. Tenant scoping in decisions runs through one choke point (internal/decision/engine.go normalizeRequest and the relationship tenant match). E2 evidence is adversarial per §13.2 and is not yet produced. Draft-8 distinguishes implemented from evidenced, so current remains E1 until that review exists. P: >- No rung applies. flex-auth holds no datastore: registry snapshot and policy package are baked into the image and mounted read-only, and the production Deployment runs with no --log flag. P0 is the framework's floor and presupposes a database. Declaring P0 would be a fabrication. R: >- No rung applies, same reason. No tenant data is persisted in production, so there is nothing to retain or erase. R0 ("kept indefinitely by default") would misdescribe a service that keeps nothing. V: >- No restart or failover exercise establishes an availability position for the complete decision path. The target is exercised V1 recovery, not an inferred claim from a Deployment manifest. provider: capability: authorization.decision axes: A: available: 3 maximum: 4 conditions: - "A3 consumers authenticate flex-auth and observe a denial at their endpoint." - "A4 requires the AuthZEN interface and records decision differences between PDPs." evidence: - "docs/tenancy-posture-review.md" evidence: E1: - "internal/decision/engine.go:188" - "internal/decision/engine.go:248" A2: - "internal/callerauth/auth.go" - "internal/callerauth/auth_test.go" - "cmd/flex-auth/main_test.go" - "charts/flex-auth/templates/rbac.yaml" - "deploy/caller-auth-rbac.yaml" - "docs/adr/0004-inbound-caller-authentication.md" deployment: "values/user-engine.yaml, values/tenant-engine.yaml, deploy/flex-auth-user-engine.yaml, deploy/flex-auth-tenant-engine.yaml"